CVE-2020-9648 is a cross-site scripting (XSS) vulnerability affecting Adobe Experience Manager versions 6.5 and earlier. This medium-severity flaw (CVSS 6.1) can be exploited remotely with low complexity, requiring user interaction, and could lead to arbitrary JavaScript execution in the victim's browser, resulting in limited impact to confidentiality and integrity. While the EPSS score suggests a relatively low likelihood of exploitation compared to other CVEs, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with a single article mentioning a Flash Player bug, not directly this AEM vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4, < 6.4.8.1CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* | ||
>= 6.5, < 6.5.5.0CPE matchmatch criteria | cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.